Техническая информация
- [HKLM\System\CurrentControlSet\Services\syshost32] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\syshost32] 'ImagePath' = '"%WINDIR%\Installer\{598F93A7-C9D6-F6A2-42E1-436B22D4F6B6}\syshost.exe" /service'
- [HKLM\System\CurrentControlSet\Services\13ca12] 'Start' = '00000001'
- [HKLM\System\CurrentControlSet\Services\13ca12] 'ImagePath' = '<DRIVERS>\13ca12.sys'
- 'syshost32' "%WINDIR%\Installer\{598F93A7-C9D6-F6A2-42E1-436B22D4F6B6}\syshost.exe" /service
- '13ca12' <DRIVERS>\13ca12.sys
- %WINDIR%\installer\{598f93a7-c9d6-f6a2-42e1-436b22d4f6b6}\syshost.exe
- <DRIVERS>\13ca12.sys
- <DRIVERS>\13ca12.sys
- из <Полный путь к файлу> в %TEMP%\bba35a46.tmp
- '%WINDIR%\installer\{598f93a7-c9d6-f6a2-42e1-436b22d4f6b6}\syshost.exe' /service
- '%WINDIR%\syswow64\cmd.exe' /C del /Q /F "%TEMP%\bba35a46.tmp" (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' -set TESTSIGNING ON (со скрытым окном)